Matches in SemOpenAlex for { <https://semopenalex.org/work/W2463095512> ?p ?o ?g. }
Showing items 1 to 59 of
59
with 100 items per page.
- W2463095512 endingPage "146" @default.
- W2463095512 startingPage "146" @default.
- W2463095512 abstract "Much computer communications activity is invisible to the user, happening without explicit permission. When system administrators investigate network communications activities, they have difficulty tracing them back to the processes that cause them. The strictly layered TCP/IP networking model that underlies all widely used, general-purpose operating systems makes it impossible to trace a packet seen on the network back to the processes that are responsible for generating and receiving it. The TCP/IP model separates the concerns of network routing and process ownership so that the layers cannot share the information needed to correlate packets to processes. But knowing what processes are responsible for communications activities can be a great help in determining whether that activity is benign or malicious. My solution combines a visualization tool, a kernel-level correlation engine, and middleware that ties the two together. My research enables security personnel to visually correlate packets to the processes they belong to helping users determine whether communications are benign or malicious. I present my discoveries about the system administrator community and relate how I created a new correlation technology. I conducted a series of initial interviews with system administrators to clarify the problem, researched available solutions in the literature, identified what was missing, and worked with users to build it. The users were my co-designers as I built a series of prototypes of increasing fidelity and conducted usability evaluations on them. I hope that my work will demonstrate how well the participatory design[10] approach works. My work has implications for the kernel structure of all operating system kernels with a TCP/IP protocol stack and network model. In light of my research, I hope security personnel will more clearly see sets of communicating processes on a network as basic computational units rather than the individual host computers. If kernel designers incorporate my findings into their work, it will enable much better security monitoring than is possible today making the Internet safer for all." @default.
- W2463095512 created "2016-07-22" @default.
- W2463095512 creator A5034401520 @default.
- W2463095512 creator A5037675411 @default.
- W2463095512 date "2006-01-01" @default.
- W2463095512 modified "2023-09-24" @default.
- W2463095512 title "Visual correlation of network traffic and host processes for computer security" @default.
- W2463095512 hasPublicationYear "2006" @default.
- W2463095512 type Work @default.
- W2463095512 sameAs 2463095512 @default.
- W2463095512 citedByCount "0" @default.
- W2463095512 crossrefType "dissertation" @default.
- W2463095512 hasAuthorship W2463095512A5034401520 @default.
- W2463095512 hasAuthorship W2463095512A5037675411 @default.
- W2463095512 hasConcept C107457646 @default.
- W2463095512 hasConcept C111919701 @default.
- W2463095512 hasConcept C136764020 @default.
- W2463095512 hasConcept C138673069 @default.
- W2463095512 hasConcept C158379750 @default.
- W2463095512 hasConcept C170130773 @default.
- W2463095512 hasConcept C38652104 @default.
- W2463095512 hasConcept C41008148 @default.
- W2463095512 hasConceptScore W2463095512C107457646 @default.
- W2463095512 hasConceptScore W2463095512C111919701 @default.
- W2463095512 hasConceptScore W2463095512C136764020 @default.
- W2463095512 hasConceptScore W2463095512C138673069 @default.
- W2463095512 hasConceptScore W2463095512C158379750 @default.
- W2463095512 hasConceptScore W2463095512C170130773 @default.
- W2463095512 hasConceptScore W2463095512C38652104 @default.
- W2463095512 hasConceptScore W2463095512C41008148 @default.
- W2463095512 hasLocation W24630955121 @default.
- W2463095512 hasOpenAccess W2463095512 @default.
- W2463095512 hasPrimaryLocation W24630955121 @default.
- W2463095512 hasRelatedWork W1182667402 @default.
- W2463095512 hasRelatedWork W1193251056 @default.
- W2463095512 hasRelatedWork W1514781912 @default.
- W2463095512 hasRelatedWork W155701930 @default.
- W2463095512 hasRelatedWork W1567353711 @default.
- W2463095512 hasRelatedWork W1704504704 @default.
- W2463095512 hasRelatedWork W1763762948 @default.
- W2463095512 hasRelatedWork W208971511 @default.
- W2463095512 hasRelatedWork W2101284766 @default.
- W2463095512 hasRelatedWork W2146244799 @default.
- W2463095512 hasRelatedWork W2165181131 @default.
- W2463095512 hasRelatedWork W2396408030 @default.
- W2463095512 hasRelatedWork W2476520752 @default.
- W2463095512 hasRelatedWork W2903012248 @default.
- W2463095512 hasRelatedWork W3028019736 @default.
- W2463095512 hasRelatedWork W3094315266 @default.
- W2463095512 hasRelatedWork W594233172 @default.
- W2463095512 hasRelatedWork W76097850 @default.
- W2463095512 hasRelatedWork W1605877857 @default.
- W2463095512 hasRelatedWork W1950463406 @default.
- W2463095512 isParatext "false" @default.
- W2463095512 isRetracted "false" @default.
- W2463095512 magId "2463095512" @default.
- W2463095512 workType "dissertation" @default.